Description
Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Composer). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Portal. While the vulnerability is in Oracle WebCenter Portal, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle WebCenter Portal accessible data as well as unauthorized read access to a subset of Oracle WebCenter Portal accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle WebCenter Portal. CVSS 3.1 Base Score 7.7 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:H/A:L).
Published: 2026-08-18
Score: 7.7 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A difficult-to-exploit weakness in the Composer component of Oracle WebCenter Portal allows an attacker with low privileges but network access via HTTP to gain unauthorized control over critical data. The flaw permits creation, deletion, or modification of portal content, causing integrity breaches, and also enables a partial denial of service that can disrupt access to the portal. The technical weakness is an instance of improper authorization that lets users perform actions beyond their intended level of access.

Affected Systems

Oracle WebCenter Portal version 12.2.1.4.0 and 14.1.2.0.0 within Oracle Fusion Middleware are affected. The vulnerability is scoped to the portal product but may also impact other components that rely on Portal services.

Risk and Exploitability

The CVSS score of 7.7 indicates high severity with significant confidentiality, integrity, and availability impact, though the exploit difficulty is high and it requires local low privilege. The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog, suggesting no publicly documented exploits yet. Based on the attack vector, a low‑privileged attacker connected to the network can exploit it via standard HTTP requests, making it a realistic threat if the portal is exposed to untrusted networks.

Generated by OpenCVE AI on August 18, 2026 at 22:54 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor‑supplied patch or upgrade to a fixed version of Oracle WebCenter Portal.
  • Implement network segmentation or firewall policies to restrict HTTP access to trusted IP ranges or VPN tunnels.
  • Enable and monitor audit logs for unexpected data creation, deletion, or modification events to detect and respond to abuse.

Generated by OpenCVE AI on August 18, 2026 at 22:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 18 Aug 2026 23:15:00 +0000

Type Values Removed Values Added
Title Authorization Bypass in Oracle WebCenter Portal Composer Component Allows Partial Data Tampering and Denial of Service
Weaknesses CWE-285

Tue, 18 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Composer). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle WebCenter Portal. While the vulnerability is in Oracle WebCenter Portal, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle WebCenter Portal accessible data as well as unauthorized read access to a subset of Oracle WebCenter Portal accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle WebCenter Portal. CVSS 3.1 Base Score 7.7 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:H/A:L).
First Time appeared Oracle
Oracle webcenter Portal
CPEs cpe:2.3:a:oracle:webcenter_portal:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:webcenter_portal:14.1.2.0.0:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle webcenter Portal
References
Metrics cvssV3_1

{'score': 7.7, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:H/A:L'}


Subscriptions

Oracle Webcenter Portal
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-08-18T20:59:03.658Z

Reserved: 2026-07-08T15:51:55.584Z

Link: CVE-2026-60733

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-18T21:16:41.210

Modified: 2026-08-18T21:16:41.210

Link: CVE-2026-60733

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-19T00:15:13Z

Weaknesses